Ch.17 Identity, Data and Cybersecurity: eIDAS 2.0, Data Act, NIS2, CRA Regulation 241 words

Data Act: cloud-switching rights, not GDPR portability

The Data Act gives you the right to switch cloud providers and port your data; the exam trap is confusing this with GDPR's right to data portability.

Аудио

Слушай тази страница (бета)

Субтитри

The Data Act (Regulation 2023/2854) targets vendor lock-in by giving you the right to switch between data-processing services like cloud providers. It requires providers to make switching easy, including porting your data and metadata within a set timeframe. The key contrast is with GDPR: GDPR's right to data portability covers personal data you provided to a controller, while the Data Act covers any data generated or processed in the cloud, including non-personal data and metadata. So if a question mentions switching cloud providers, think Data Act; if it mentions moving personal data from a social media platform, think GDPR.

To avoid the trap, remember that the Data Act applies to all data in the cloud service, not just personal data. A quick elimination trick: if the scenario involves a business moving its entire database or application from one cloud to another, that's Data Act territory. If it's an individual exporting their photos or contacts from a service, that's GDPR. Also note that the Data Act imposes specific switching charges caps and requires providers to make switching technically feasible within 30 days. If an exam option mentions 'free switching' or 'immediate portability', check the context carefully.

To lock this in, think: 'Cloud switch? Data Act. Personal data move? GDPR.' For a memory check, ask yourself: which law would cover a company moving its customer database from AWS to Azure? That's the Data Act, because it's about the service, not just personal data.

Свързана флашкарта

Which EU law supports switching between data-processing services such as cloud providers?

The Data Act.

Обратно към флашкартата Виж всички флашкарти